< ciso
brief />
Tag Banner

All news with #secrets management tag

60 articles

AWS Secrets Manager adds security posture recommendations

🔒 AWS Secrets Manager now integrates with the AWS Recommended Actions framework to display contextual, actionable suggestions directly in the Secrets Manager console. Users can view tailored recommendations beside individual secrets to improve security posture and follow best practices without leaving the console. Examples include enabling rotation, switching to customer-managed keys for encryption, and addressing configuration improvements. This capability is available in all AWS Regions where Secrets Manager is offered, at no additional cost.
read more →

Leaked GitHub App keys risk organization takeover

🔐 GitGuardian discovered hundreds of publicly exposed GitHub App private keys that remain valid unless manually revoked. Their testing found many keys granted read or write access to private repositories and some allowed organization administration, enabling potential takeovers. The exposed keys included apps used by multiple organizations and internal one-off bots, increasing supply-chain risk. Experts recommend routine key rotation and prompt revocation to limit long-lived exposure.
read more →

Transfer Family SFTP connectors support credential rotation

🔒 AWS Transfer Family SFTP Connectors now continue file transfers while you rotate authentication credentials, eliminating the need to repoint connectors to new secret versions. Connectors can retrieve credentials from an ordered list of AWS Secrets Manager version stages (for example, current and previous) and will try each version in sequence until authentication succeeds. This behavior is configured when creating or updating a connector, requires storing credentials in AWS Secrets Manager, and is available in all Regions where Transfer Family SFTP Connectors are supported.
read more →

OpenClaw issues broad 2.0 overhaul for agents

🔧 OpenClaw released its largest update, a system-wide overhaul touching installation, runtime, memory, plugins, security and user-facing apps in version 2026.8.1. Built by hundreds of contributors, the release improves secret handling, runtime isolation and plugin lifecycle controls to reduce unintended data exposure. The update grew from usability fixes into a full rewrite to support scale and consistent controls across integrations.
read more →

AWS adds one‑click install for Workload Credentials

🛠️ AWS Secrets Manager now offers one‑click installation for the AWS Workload Credentials Provider (AWCP) on Amazon Linux and Windows, replacing a prior multi‑step build-from-source flow. Pre-built, code-signed binaries for Linux (x86_64, ARM64) and Windows (x64) are available via public download and the Amazon Linux repository, enabling one-command install on Amazon Linux EC2. AWCP resolves secrets from AWS Secrets Manager, caches them in memory, and exposes them via a local HTTP endpoint; it also retrieves certificates from AWS Certificate Manager. The feature is available in all Regions where Secrets Manager is offered at no extra charge beyond standard Secrets Manager pricing.
read more →

Securing AI Gateways and Control Plane Targets

🔒 Microsoft describes attacks targeting AI infrastructure components such as gateways, retrieval platforms, orchestration services, and container runtimes that centralize credentials and execution privileges. Observed intrusions against LiteLLM, RAGFlow, and Kestra aimed to harvest secrets, persist on hosts, and monetize compute. The advisory emphasizes inventorying exposed AI surfaces, restricting administrative access, and monitoring gateway-originated execution and secret access to mitigate risk.
read more →

Secrets Manager Adds Cisco and Netskope Rotations

🔒 AWS Secrets Manager now supports managed external secrets for Cisco Security Platform API keys and Netskope API tokens, allowing automated rotation directly from the AWS console without custom rotation code. Cisco rotations refresh the API key's refresh token on a schedule so applications continue to obtain short-lived access tokens. Netskope rotations update RBACv3 service-account tokens via SCIM and validate the new token before completion. These self-authenticating integrations require no separate administrator credential and are available in all Regions where managed external secrets are supported.
read more →

MCP Server Risks: Protecting Enterprise AI Secrets

🔒 The Model Context Protocol (MCP) enables AI agents to access tools and data across enterprise systems, but the MCP server often stores credentials, tokens and keys that can expose an organization if mishandled. Common risks include plaintext config files, credential sprawl, prompt injection, over-permissioning and untrusted exposed servers. Mitigations include centralizing secrets, using short-lived credentials, enforcing least privilege, human approval for sensitive actions, end-to-end encryption, thorough logging and inventorying MCP servers.
read more →

AWS Secrets Manager Adds Jenkins and SonarQube Token Rotation

🔐 AWS Secrets Manager now supports managed external secrets for Jenkins API Tokens and SonarQube Tokens, enabling automatic rotation and lifecycle management directly from the AWS console. For Jenkins, Secrets Manager mints new tokens and revokes old ones only after verifying the replacement is active, supporting both self-rotation and admin-assisted rotation. SonarQube rotation covers User Tokens, Global Analysis Tokens, and Project Analysis Tokens via the SonarQube Web API, with user tokens supporting self-rotation and analysis tokens rotated using an admin token. These additions join other supported services and are available in all Regions where managed external secrets is supported.
read more →

Secrets Manager publishes secret update events

🔔 AWS Secrets Manager now publishes events to Amazon EventBridge when secret values change, enabling event-driven responses without parsing CloudTrail. You can create EventBridge rules to detect active secret value changes and route them to targets like AWS Lambda, Amazon SNS, Amazon SQS, or Amazon Step Functions. Notifications are published to the default event bus automatically, require no opt-in, and are available in all Regions where AWS Secrets Manager is offered at no extra cost.
read more →

AI-Accelerated Cloud Attack Exploits Management Gaps

🔎 A Sygnia report details how a lone threat actor leveraged AI to complete in 72 hours what would normally take weeks, using established cloud attack techniques rather than novel exploits. The attacker obtained an AWS access key via an internet-facing app and used agentic AI workflows to search for secrets, establish persistence, exfiltrate RDS data, and perform impact actions. The report highlights gaps in secrets management, identity governance, deployment workflows and visibility, and provides containment recommendations for defenders.
read more →

AWS Secrets Manager adds Paddle and GitLab support

🔐 AWS Secrets Manager now supports managed external secrets for Paddle API Keys and GitLab Access Tokens. This feature enables automatic rotation of third-party credentials directly from AWS Secrets Manager, using Paddle's native rotation API and GitLab's atomic rotation mechanism. Customers can rotate Paddle API keys with a configurable grace period and rotate GitLab Personal, Group, and Project Access Tokens. These integrations join existing partners and are available in all Regions where managed external secrets is supported.
read more →

Start Post‑Quantum Cryptography with Credentials

🔐 Today’s public-key cryptography faces a future threat from quantum computers that can render intercepted ciphertext and stored credentials decryptable. Agencies like the NSA and standards bodies such as NIST have set Q-day deadlines between 2027 and 2035 to phase in quantum-resistant algorithms, while enterprises face multi-year migrations. A practical approach is credentials-first: inventory secrets, prioritize long-lived, high-impact credentials, adopt hybrid cryptography, and design for crypto-agility to reduce Harvest Now, Decrypt Later risks.
read more →

Agent Toolkit Adds Secret Safety Skill for Agents

🔒 AWS Secrets Manager introduces a secret safety skill in the aws-core plugin for the Agent Toolkit for AWS, enabling AI coding agents to use secrets without exposing values to models or session logs. The skill prevents models from requesting raw secret values and prompts developers to clarify intent while constructing commands that reference secrets. A child process resolves secret references at execution time, keeping plaintext secrets out of agent context and logs. The feature is available across supported agent harnesses and Regions where Secrets Manager is offered.
read more →

Governing the growing ghost workforce risk

🛡️ Enterprises are facing an invisible workforce: non-human identities (bots, service accounts, API keys, tokens, certificates) that now often outnumber humans. These ghost identities authenticate constantly across environments and, when unmanaged, accumulate privileges and risks. The industry has seen incidents where forgotten or third-party machine identities enabled widespread breaches, and a looming 2026 certificate-expiration wave threatens cascading outages. Organisations must prioritise governance—discovering NHIs, assigning ownership, auditing privileges, and addressing imminent certificate expirations—before tool selection.
read more →

AWS launches Workload Credentials Provider for certs

🔒 AWS announced the AWS Workload Credentials Provider, a lightweight client-side tool that automates export and deployment of certificates from AWS Certificate Manager and local caching of secrets from AWS Secrets Manager. It removes the need for custom EventBridge-based automation for certificate renewals, supports Windows and Linux, and works with Apache and NGINX. The provider is open source and compatible with Secrets Manager Agent functionality.
read more →

AgentCore Identity supports customer-managed secrets

🔐 Amazon Bedrock AgentCore Identity now lets customers reference existing AWS Secrets Manager secret ARNs directly in Credential Providers. Previously, secrets were service-managed and created by AgentCore Identity, limiting tagging, CMK encryption, and governance controls. Customers can now create and manage secrets with their own policies and then reference the ARN without changing runtime behavior. This feature is GA in 14 AWS Regions.
read more →

Well‑Architected Software Supply Chain Best Practices

🔒 This AWS Security blog post outlines best practices for defending against software supply chain attacks, motivated by recent npm incidents like Shai‑Hulud and axios. It emphasizes reducing long‑lived credentials by using temporary credentials (AWS CLI login, IAM Identity Center, OIDC) and centralizing secrets with AWS Secrets Manager or Systems Manager Parameter Store. The article advocates layered defenses including MFA, multi‑approver workflows, artifact signing with AWS Signer, central package repositories using CodeArtifact, image scanning with Amazon Inspector, and provenance attestations for npm packages.
read more →

AWS Secrets Manager adds Datadog and Snowflake support

🔐 AWS Secrets Manager now supports managed external secrets for Datadog vended keys and Snowflake Programmatic Access Tokens, enabling automatic rotation of third-party credentials directly within Secrets Manager. The update covers Datadog API keys, Application keys, and admin credential pairs for service accounts. For Snowflake, Secrets Manager can rotate Programmatic Access Tokens using Snowflake's native authentication and offers a configurable grace period to minimize disruption. These additions join existing integrations such as BigID, Confluent Cloud, MongoDB Atlas, and Salesforce and are available in all Regions where managed external secrets is supported.
read more →

Practical Guidance for Securing Google API Keys

🔐 This post explains why API keys are sensitive credentials for accessing Google AI and Cloud services and why careless handling leads to misuse or billing abuse. It outlines simple, actionable steps: create keys in dedicated projects, apply API and application restrictions, and store keys in Secret Manager or equivalent. The article also covers detection and response—how to list keys, monitor usage metrics, delete compromised keys, and rotate keys to reduce risk.
read more →